search
FortiMail
Trends
- 1Citrix and Fortinet zero-days under active exploitation●Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-10428
Security researchers warn that newly disclosed zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) are being actively exploited, with critical infrastructure and government organisations among the targets. Apple has separately patched a CoreGraphics flaw already used in attacks. Administrators are urged to apply patches urgently and review systems for signs of compromise.
- 2Pentagon Data Breach and Apple Zero-Days Dominate Security News▼Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories
A cybersecurity newsletter bulletin rounds up more than 20 stories, headlined by a data breach at the Pentagon alongside newly disclosed zero-day vulnerabilities in Citrix, Fortimail and Apple products. The roundup highlights an unusually busy stretch for security teams, with flaws affecting widely used enterprise and consumer software requiring urgent patching and attention.
- 3CISA Flags Actively Exploited Critical FortiMail Flaw●CISA adds CVE-2026-104286 (CVSS 9.8) to KEV—critical flaw in Fortinet FortiMail allowing unauthenticated attackers to wr
CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog after reports of active attacks. The flaw, rated 9.8 out of 10 in severity, affects Fortinet's FortiMail and lets unauthenticated attackers write arbitrary files on vulnerable servers. Security teams are urged to patch immediately, as the flaw is described as a zero-day already being exploited in the wild.
- 4Fortinet urges immediate patching of FortiMail installations●RESOLUTION NOTES: Patch your FortiMail installations immediately and monitor Fortinet's vendor advisories, or we will cl
Security responders are telling organizations to patch their FortiMail installations immediately and to follow Fortinet's vendor advisories closely. The message comes in a blunt, half-joking incident-response note warning that tickets will be closed as 'user refused to help themselves' if admins ignore the patching guidance. The advice underscores that unpatched FortiMail systems remain a live risk and that defenders should treat Fortinet advisories as urgent action items, not background reading.
- 5FortiMail zero-day actively exploited with no patch available●2026-W40 — Weekly Threat Roundup 🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patc
A weekly threat roundup reports that a zero-day vulnerability in Fortinet's FortiMail, tracked as CVE-2026-104286, is being actively exploited while no patch is available, forcing administrators to rely on interim workarounds. The same roundup notes Operation KillSwitch dismantled the KillSec ransomware group, allegedly run by a 16-year-old, with seizures reportedly carried out.
- 6Fortinet FortiMail Bug CVE-2026-104286 Actively Exploited●Fortinet FortiMail CVE-2026-104286 Actively Exploited: Critical Path Traversal and NULL Byte Vulnerability Alert
Fortinet has a critical vulnerability, tracked as CVE-2026-104286, in its FortiMail email security product. The flaw involves path traversal combined with NULL byte handling, and security researchers report it is being actively exploited in the wild. Administrators are being urged to apply patches immediately to prevent attackers from compromising mail servers.